Security and control

Your advertising accounts remain under your control.

AdSpend Lens is designed around read-only permissions, encrypted credentials, strong tenant separation and clear disconnection and deletion processes.

Read-only connectionAnalysis access—not campaign control
Read reporting data
Read campaign structure
Change budgets
Pause adverts
You can disconnect the account when required.
Security principles

Access only what the product needs to explain performance.

Security is not a single feature. It covers permissions, credential handling, data separation, background jobs, auditing, deletion and honest warnings when the connection is no longer healthy.

01

Read-only by default

Advertising connections request reporting access rather than the ability to create, edit, pause or delete campaigns.

02

Encrypted token storage

OAuth access and refresh credentials are intended to be encrypted at rest and never exposed to the customer browser.

03

Strong tenant separation

Every query and background job must be scoped to the correct customer, business and selected advertising account.

04

Stored synchronised data

Dashboards use data stored in AdSpend Lens rather than calling Meta or Google whenever a filter changes.

05

Audit and sync logs

Connection changes, sync runs, failures and important administrative actions are recorded.

06

Disconnect and deletion controls

Customers should be able to revoke access and request removal of stored advertising information through a defined process.

What read-only means

AdSpend Lens can analyse. It cannot manage the campaigns.

The platform is intended to retrieve permitted reporting data, creative information and account settings required for analysis. It should not request broader permissions simply because they are convenient.

Designed to allowRead campaign structuresRead performance insightsRead creative informationSynchronise historical reporting data
Not designed to allowChange budgetsPause or activate advertsEdit targeting or bidsCreate or delete campaigns
How data moves through the product

A controlled route from advertising platform to customer dashboard.

1Secure OAuth connection

The customer approves the permitted advertising account access.

2Encrypted credential storage

Tokens remain server-side and protected at rest.

3Background synchronisation

Workers retrieve permitted reporting data on a schedule.

4Tenant-scoped dashboard

Stored data is served only to the correct customer and business.

Operational honesty

Security also means saying when the data is stale or incomplete.

A polished dashboard should never hide a broken permission, failed synchronisation or unavailable field. The customer needs to know whether the analysis reflects the latest account data.

Connection healthNeeds attention
Meta AdsUpdated 18 minutes ago
Google AdsPermission expires soon
Last complete snapshot30 July 2026 · 14:20

Reconnect Google Ads before the next scheduled import.

Expired permissionTell the customer when an account needs reconnecting.
Stale syncShow when the latest data was successfully received.
API limitationExplain when a field is unavailable for a campaign type.
Deletion requestTrack removal across active and historical data.
Independent advertising visibility

Independent visibility should not require giving up control.

AdSpend Lens is designed to remain read-only, transparent and removable whenever the customer decides to disconnect.

View the product demo